Should support showing signatures

Bug #91931 reported by Jelmer Vernooij
2
Affects Status Importance Assigned to Milestone
Bazaar GTK+ Frontends
Fix Released
Wishlist
Daniel Schierbeck

Bug Description

It should be possible to see what signatures exist on a particular
revision in bzr-gtk.

Tags: revisionview
Jelmer Vernooij (jelmer)
Changed in bzr-gtk:
status: Unconfirmed → Confirmed
description: updated
Changed in bzr-gtk:
assignee: nobody → dasch
importance: Undecided → Wishlist
Changed in bzr-gtk:
status: Confirmed → In Progress
Revision history for this message
James Henstridge (jamesh) wrote :

The signature code in revisionview.py seems to be missing a particularly important feature: checking whether the signed revision testament matches the actual revision.

Without doing that I can tamper with a branch while leaving the signatures as is, and bzr-gtk will pretend that the revision is okay.

Revision history for this message
Daniel Schierbeck (dasch) wrote : Re: [Bug 91931] Re: Should support showing signatures

On Fri, 2008-05-02 at 06:41 +0000, James Henstridge wrote:
> The signature code in revisionview.py seems to be missing a particularly
> important feature: checking whether the signed revision testament
> matches the actual revision.
>
> Without doing that I can tamper with a branch while leaving the
> signatures as is, and bzr-gtk will pretend that the revision is okay.

Yes, that is a very real and important concern. I'll have a look at it
as soon as possible, but I won't be home until Monday. Is there an easy
way to generate a testament for a revision, so that it can be compared
to the signed one?

Cheers,
Daniel

Jelmer Vernooij (jelmer)
Changed in bzr-gtk:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Related blueprints

Remote bug watches

Bug watches keep track of this bug in other bug trackers.